FHE from discrete log assumption is hopeless. FHE from group action (acting on, say some k-algebra) seems possible (group action providing security, and k-algebra providing FHE `eval` functionality)!
Hard to come by...
Does AWS F1 instances (one with FPGA) have a per-user hardware root of trust? Is there a way to do remote attestation on the FPGA before loading the bitfile? (I know Ultrascale MPSocs have a (kludgy) PUF based RoT, but want it for F1 instances.)
“Sir, I don’t just suffer from stupid, I am, in fact stupid…”
In my defense, attacks are only supposed to get better, not dramatic + the “smoothness situation” seemed similar to Bala/Koblitz embedding degree situation, but now its more like the Bonnie situation. #pulpfiction
I'm too Flu-ed up (it's not covid) to read anything ATM, but if there's a fix for SIDH, I'll use it provided it's no more than 2x slower.
Also, like MOV => PBC, please do more than just fix SIDH, use the attack to plant a trapdoor. And no patents, please.
Back to bed.
I'm too Flu-ed up (it's not covid) to read anything ATM, but if there's a fix for SIDH, I'll use it provided it's no more than 2x slower.
Also, like MOV => PBC, please do more than just fix SIDH, use the attack to plant a trapdoor. And no patents, please.
Back to bed.
Worthwhile pointing out that Ben Smith has a very readable paper on Richelot Isogeny https://t.co/yo2BNhB8Hz along with his Ph.D. thesis (less readable).
Like most math research papers, it's not possible to absorb everything over a weekend😢😢😢
@FouotsaB@asanso@durumcrustulum@mstrakastrak The other option could be to _somehow_ ensure that c = 2^a - 3^b has a large factor. Since Velu is exponential time, if Velu is the best way to compute \gamma(P_0), then computing \gamma(P_0) itself would be infeasible if c has a large factor (even with known factors of c).
@asanso@durumcrustulum@mstrakastrak On first read, the attack also seem to crucially depend on the factorization of 2^a - 3^b to compute the 2^a - 3^b image of P0 and Q0.
In function fields, I always thought LLL computes short basis within _constant_ approx factor in _poly_ time. (I think Prof. Paulus has a paper on it.)
Now Crypto has a paper titled "On Codes and Learning with Errors over Function Fields" doing some reductions...
#ShouldRead
I’m curious how much it will cost to build an analog circuit that can sample below smoothing parameters for NIST pqc candidates?
Since Gaussian distribution gives more weight to small vectors, merely sampling poly times can solve SVP whp. — assuming you can build such a sampler!
Weekend plan: Implement a DGS sampler in FPGA that uses an analog AWGN generator with an analog BP filter+accumulator+ADC to solve for SVP (basically _exploit_ Regev/Maccianco worst/average case reduction with the help of analog hardware)
Achievement: Zilch 👎
On top of all this, medical records are labeled highly inconsistently. (Yes, DICOM, ICD-10, etc. make the _labels consistent_, but the doctors and nurses who label the data are not. Many doctors apparently reneg their own diagnosis when presented with same case again!)
3/n
Unpopular opinion: Healthcare AI is _not_ being hampered by lack of privacy enhancing tech. (PETs).
From the little I understand about "deep learning" (aka giant fuzzy table lookups), looking at the data and tweaking the model is precisely what makes more data valuable.
1/n
Running training algorithms blind just reinforces the biases the of the model instead of making the "trained on large dataset" model more robust.
A practical comparison between supervised learning with PETs and purely unsupervised learning will be very interesting.
2/n